I’m Arnau, a Red Teamer and pentester based in Spain, doing offensive security engagements for clients across critical sectors.
My day-to-day involves the full attack lifecycle: social engineering, breaking into networks, moving through Active Directory environments, evading defenses, and writing the reports that explain what happened and why it matters. I work with custom tooling, C2 frameworks, and the kind of tradecraft that keeps blue teams on their toes.
Before going full-time in offensive security, I studied Computer Engineering at UPV (Valencia) and spent a semester at Metropolia University in Helsinki doing hands-on ethical hacking labs and exercises. I’ve been building my skills through certifications and self-study since university, and I currently hold OSCP+, CRTO, OSWP, eJPTv2, and ICCA.
This blog is where I write about what I know: red team tradecraft, evasion techniques, malware development concepts, AI applied to offensive security, and lessons from the field. Everything here comes from real experience, no filler, no theory without practice.
When I’m not breaking into things for a living, I train for triathlons and ride through the mountains around Alcoy.